<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 13:01:05 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0463 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Elles permettent à un attaquant de provoqu…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0463</link>
      <description>certfr-2026-avi-0463</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0463</guid>
    </item>
    <item>
      <title>EUVD-2026-278519</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-278519</link>
      <description>EUVD-2026-278519</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-278519</guid>
    </item>
    <item>
      <title>fkie_cve-2026-34445</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-34445</link>
      <description>&lt;p&gt;Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, the ExternalDataInfo class in ONNX was using Python’s setattr() function to load metadata (like file paths or data lengths) directly from an ONNX model file. It didn’t check if the &amp;#34;keys&amp;#34; in the file were valid. Due to this, an attacker could craft a malicious model that overwrites internal object properties. This issue has been patched in version 1.21.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, the ExternalDataInfo class in ONNX was using Python’s setattr() function to load metadata (like file paths or data lengths) directly from an ONNX model file. It didn’t check if the &amp;#34;keys&amp;#34; in the file were valid. Due to this, an attacker could craft a malicious model that overwrites internal object properties. This issue has been patched in version 1.21.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-34445</guid>
    </item>
    <item>
      <title>GHSA-538c-55jv-c5g9 — ONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings.</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-538c-55jv-c5g9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: onnx&lt;/p&gt;
&lt;p&gt;### Summary
The ExternalDataInfo class in ONNX was using Python’s setattr() function to load metadata (like file paths or data lengths) directly from an ONNX model file. The problem? It didn’t check if the &amp;#34;keys&amp;#34; in the file were valid. Because it blindly trusted the file, an attacker could craft a malicious model that overwrites internal object properties.&lt;/p&gt;
&lt;p&gt;### Why its Dangerous
**Instant Crash DoS**: An attacker can set the length property to a massive number like 9 petabytes. When the system tries to load the model, it attempts to allocate all that RAM at once, causing the server to crash or freeze Out of Memory.&lt;/p&gt;
&lt;p&gt;**Access Bypass**: By setting a negative offset -1, an attacker can trick the system into reading parts of a file it wasn&amp;#39;t supposed to touch.&lt;/p&gt;
&lt;p&gt;**Object Corruption**: Attackers can even inject &amp;#34;dunder&amp;#34; attributes like __class__ to change the object&amp;#39;s type entirely, which could lead to more complex exploits.&lt;/p&gt;
&lt;p&gt;**Fixed**: https://github.com/onnx/onnx/pull/7751 object state corruption and DoS via ExternalDataInfo attribute injection&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: onnx&lt;/p&gt;
&lt;p&gt;### Summary
The ExternalDataInfo class in ONNX was using Python’s setattr() function to load metadata (like file paths or data lengths) directly from an ONNX model file. The problem? It didn’t check if the &amp;#34;keys&amp;#34; in the file were valid. Because it blindly trusted the file, an attacker could craft a malicious model that overwrites internal object properties.&lt;/p&gt;
&lt;p&gt;### Why its Dangerous
**Instant Crash DoS**: An attacker can set the length property to a massive number like 9 petabytes. When the system tries to load the model, it attempts to allocate all that RAM at once, causing the server to crash or freeze Out of Memory.&lt;/p&gt;
&lt;p&gt;**Access Bypass**: By setting a negative offset -1, an attacker can trick the system into reading parts of a file it wasn&amp;#39;t supposed to touch.&lt;/p&gt;
&lt;p&gt;**Object Corruption**: Attackers can even inject &amp;#34;dunder&amp;#34; attributes like __class__ to change the object&amp;#39;s type entirely, which could lead to more complex exploits.&lt;/p&gt;
&lt;p&gt;**Fixed**: https://github.com/onnx/onnx/pull/7751 object state corruption and DoS via ExternalDataInfo attribute injection&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-538c-55jv-c5g9</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-34445 — ONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings.</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-34445</link>
      <description>msrc_CVE-2026-34445</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-34445</guid>
    </item>
    <item>
      <title>PYSEC-2026-2240</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-2240</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: onnx&lt;/p&gt;
&lt;p&gt;Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, the ExternalDataInfo class in ONNX was using Python’s setattr() function to load metadata (like file paths or data lengths) directly from an ONNX model file. It didn’t check if the &amp;#34;keys&amp;#34; in the file were valid. Due to this, an attacker could craft a malicious model that overwrites internal object properties. This issue has been patched in version 1.21.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: onnx&lt;/p&gt;
&lt;p&gt;Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, the ExternalDataInfo class in ONNX was using Python’s setattr() function to load metadata (like file paths or data lengths) directly from an ONNX model file. It didn’t check if the &amp;#34;keys&amp;#34; in the file were valid. Due to this, an attacker could craft a malicious model that overwrites internal object properties. This issue has been patched in version 1.21.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-2240</guid>
    </item>
    <item>
      <title>RHSA-2026:65126 — Red Hat Security Advisory: RHOAI 2.25.11 - Red Hat OpenShift AI</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:65126</link>
      <description>&lt;p&gt;crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate org.codehaus.plexus:plexus-utils: Plexus-utils: Directory Traversal in extractFile method path-to-regexp: path-to-regexp: Denial of Service via crafted regular expressions undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing org.eclipse.parsson/parsson: Eclipse Parsson: Denial of Service via uncontrolled resource consumption in JSON parsing undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames nltk: NLTK: Information disclosure via path traversal vulnerability brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity vertx-core: Eclipse Vert.x: Information disclosure via improper handling of HTTP 30x redirects guardrails-detectors: guardrails-detectors: Unauthenticated Regular-Expression Denial of Service (ReDoS) via detector_params.regex guardrails-detectors: guardrails-detectors: SSRF and local file read via user-supplied XML Schema (xml-with-schema:) trustyai-service-operator: trustyai-service-operator: TAS internal Service bypasses kube-rbac-proxy, exposing unauthenticated Quarkus API cluster-wide odh-dashboard: odh-dashboard: Backend port 8080 trusts x-forwarded-access-token without origin validation data-science-pipelines-operator: DSPO: Operator ClusterRole grants…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate org.codehaus.plexus:plexus-utils: Plexus-utils: Directory Traversal in extractFile method path-to-regexp: path-to-regexp: Denial of Service via crafted regular expressions undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing org.eclipse.parsson/parsson: Eclipse Parsson: Denial of Service via uncontrolled resource consumption in JSON parsing undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames nltk: NLTK: Information disclosure via path traversal vulnerability brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity vertx-core: Eclipse Vert.x: Information disclosure via improper handling of HTTP 30x redirects guardrails-detectors: guardrails-detectors: Unauthenticated Regular-Expression Denial of Service (ReDoS) via detector_params.regex guardrails-detectors: guardrails-detectors: SSRF and local file read via user-supplied XML Schema (xml-with-schema:) trustyai-service-operator: trustyai-service-operator: TAS internal Service bypasses kube-rbac-proxy, exposing unauthenticated Quarkus API cluster-wide odh-dashboard: odh-dashboard: Backend port 8080 trusts x-forwarded-access-token without origin validation data-science-pipelines-operator: DSPO: Operator ClusterRole grants…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:65126</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-34445</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-34445</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: onnx, Ubuntu:Pro:24.04:LTS: onnx, Ubuntu:25.10: onnx, Ubuntu:26.04:LTS: onnx&lt;/p&gt;
&lt;p&gt;Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, the ExternalDataInfo class in ONNX was using Python’s setattr() function to load metadata (like file paths or data lengths) directly from an ONNX model file. It didn’t check if the &amp;#34;keys&amp;#34; in the file were valid. Due to this, an attacker could craft a malicious model that overwrites internal object properties. This issue has been patched in version 1.21.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: onnx, Ubuntu:Pro:24.04:LTS: onnx, Ubuntu:25.10: onnx, Ubuntu:26.04:LTS: onnx&lt;/p&gt;
&lt;p&gt;Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, the ExternalDataInfo class in ONNX was using Python’s setattr() function to load metadata (like file paths or data lengths) directly from an ONNX model file. It didn’t check if the &amp;#34;keys&amp;#34; in the file were valid. Due to this, an attacker could craft a malicious model that overwrites internal object properties. This issue has been patched in version 1.21.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-34445</guid>
    </item>
  </channel>
</rss>
